Insecure Permissions in Confluent Ansible 5.5.x and 6.0.0
CVE-2021-33923

5.5MEDIUM

Key Information:

Vendor

Confluent

Vendor
CVE Published:
29 September 2021

What is CVE-2021-33923?

In Confluent Ansible versions 5.5.0, 5.5.1, 5.5.2, and 6.0.0, insecure permission settings allow local attackers to gain unauthorized access to sensitive information such as private keys and the state database. This vulnerability can lead to potential theft and misuse of critical configuration data, posing a significant security risk for organizations using these versions.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.